Cloud Threat Landscape
  • Incidents
  • Actors
  • Techniques
  • Defenses
  • Tools
  • Targeted Technologies
  • Posters & Newspapers
  • About
  • RSS
  • STIX
  • Back to wiz.io
Cloud Threat Landscape
/Incidents
Incidents
/
Long-Term Email Breach at OCC Exposes Sensitive Bank Oversight Data

Long-Term Email Breach at OCC Exposes Sensitive Bank Oversight Data

Type
Incident
Actors
❓Unknown
Pub. date
April 8, 2025
Initial access
Unknown
Impact
Data exfiltration
References
https://www.bloomberg.com/news/articles/2025-04-08/hackers-spied-on-100-bank-regulators-emails-for-over-a-year
Status
Finalized
Last edited
Apr 20, 2025 11:14 AM

Hackers infiltrated the Office of the Comptroller of the Currency (OCC) and monitored email accounts of approximately 103 bank regulators for over a year, accessing around 150,000 sensitive messages. The attackers gained entry via an administrative account, allowing them to observe communications from senior officials, including those responsible for international banking and supervisory processes. The breach, detected in early 2025 after Microsoft flagged unusual behavior, has been described as a major security incident with potentially damaging consequences for public confidence in financial oversight.

While the OCC has not confirmed attribution, the incident mirrors recent state-sponsored espionage operations, including Chinese-linked intrusions into the U.S. Treasury and telecom networks. The compromised emails reportedly contained confidential assessments of the financial health of federally regulated institutions. Although OCC stated there’s no immediate impact on the financial sector, the scale and sensitivity of the breach have raised serious concerns, prompting notifications to Congress and CISA.

Made with 💙 by Wiz

Last Updated: April 3, 2025